Gateway eSIM Credential Management for Resource-Constrained IoT Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Resource-constrained client devices, such as sensor and actuator devices, lack the capability to store and manage credentials for secure communication with application servers, as they have limited processing power and no secure storage or user interface.
Innovation Solution
A method where a gateway requests, receives, and stores an electronically transferable subscriber identity module (eSIM) associated with the client device, allowing the gateway to provide credentials for authentication and secure communication without the need for the client device to manage secure storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If client devices store credentials locally for secure communication, then authentication and secure communication capabilities are improved, but device complexity and security requirements increase significantly
Solution Approach 1:
The patent extracts the credential storage function from the client device and relocates it to the gateway. The gateway downloads eSIM credentials from the HSS and stores them in its own secure storage, while client devices only retain minimal identifiers. This extraction resolves the contradiction by maintaining authentication capability while eliminating the need for secure storage in constrained devices.
Solution Approach 2:
The gateway acts as an intermediary between the client device and the application server. It holds the credentials in secure storage and presents them to the server on behalf of the client device during authentication. This intermediary role allows the client device to authenticate without ever possessing the actual credentials, resolving the contradiction between authentication capability and secure storage requirements.
2Reliability
If client devices handle credential management, then authentication control is improved, but processing power and resource requirements increase
Solution Approach 1:
The patent extracts the credential management function from the client device and consolidates it at the gateway. The gateway performs all credential operations including downloading from HSS, secure storage, and presentation to servers. Client devices only need to provide minimal identifiers and receive authentication results, dramatically reducing their processing requirements while maintaining authentication control.
Solution Approach 2:
The gateway provides self-service credential management for multiple client devices. It automatically downloads, stores, and manages credentials without requiring each client device to have independent credential management capabilities. This centralizes the processing burden on the gateway while freeing client devices from complex authentication control tasks.
3Productivity
If multiple client devices share a gateway, then resource utilization is improved, but credential management complexity increases
Solution Approach 1:
The gateway is designed as a universal credential management platform that serves multiple client devices with different capabilities. It implements a unified credential management system that handles diverse authentication scenarios (3GPP credentials, EAP-TLS, certificate-based authentication) through a single infrastructure, resolving the contradiction by providing multi-functional credential management that scales with the number of client devices.
Solution Approach 2:
The gateway creates and manages separate credential instances for each client device in its database, associating each eSIM with the appropriate client device identifier. This copying approach allows the gateway to serve multiple clients with individualized credentials while maintaining a centralized management system, thus improving resource utilization without proportionally increasing complexity.
Data Source
AI summary
It is presented a method, executed in a gateway, the gateway being arranged to facilitate communication between a client device and an application server. The method comprises the steps of: sending a request for an electronically transferable subscriber identity module, the request comprising an identifier based on an identity of the client device; receiving a response indicating that an electronically transferable subscriber identity module, generated based on the identifier, is available; downloading the electronically transferable subscriber identity; and storing the electronically transferable subscriber identity module with an association to the client device, along with any previously stored electronically transferable subscriber identity modules. A corresponding gateway, computer program and computer program product are also presented.


